PS3 Official Firmware 4.81 Exploit - Software Downgrader & More Incoming! Could SuperSlim be hacked?

Discussion in 'PS3 News' started by STLcardsWS, Nov 9, 2017.

By STLcardsWS on Nov 9, 2017 at 6:45 PM
  1. 6,195
    3,891
    123
    STLcardsWS

    STLcardsWS Administrator

    Joined:
    Sep 18, 2014
    Messages:
    6,195
    Likes Received:
    3,891
    Trophy Points:
    123
    {NOTICE: OFFICIAL FIRMWARE 4.82 has been Released by SONY, DO NOT UPDATE}
    It was nearly 7 years ago since we have seen a PS3 Official Firmware Exploited (3.55 being the last), which predates many PS3 models and thus why those later Slim & SuperSlim models could never install Custom Firmware (CFW) and/or Downgrade. However that could all change as a team of three have been developing a new project
    (4.81 OFW Exploit) called PS3Xploit. The "Unhackable PS3 models" will be a term of the past, but the exploits not quite there yet but the possibility of a HENkaku (vita) style hack is very plausible. Currently the exploit has allowed for access to enable Flash dumps on all consoles, Then Write access to Flash, unhackables (25xx +) will not be able to write but all previous PS3 will so that means Goodbye Hardware Flashers and Hello Software Downgradrs. The team is consisting of psx-place's very own @bguerville, @esc0rtd3w and W form the team behind PS3Xploit.

    The theory behind the project started off when bguerville was looking through some of the webkit source code (for unrelated research) and stumbled on a discovery and a discussion here on the psx-place forums was formed with theories on how the PS3 could be attacked with his findings. As time passed the team formed and an idea became a full-fledged project in development, A request came to temporary remove the said discussion as the idea spawned a project with alot of potential. Sadly this is not ready for release quite yet (but soon), while we know it is working there is additional development needed to make this complete. The team has a goal of 2018 (first Q1) target for the release of the exploit.

    PS3 SuperSlim.jpg


    Recently team member esc0rtd3w announced the tentative release date on another forum and it seemed some were so grateful they decided to intrude and breach his MEGA account and leak what they thought was the exploit / key component but was only a small puzzle piece of the entire thing and quite useless itself . While the good news it did not harm the project or discourage the development team behind Ps3Xploit. However esc0rtd3w did lose some personal files and also the community lost the huge collection of NoPSN Apps for the PS3. But don't cancel those subscription service's just yet, as esc0rtd3w is in the process of re-uploading the collection, you can follow the progress here .


    Also, I have been personally told by the team that some of the details being reported elsewhere are not 100% accurate, but rest assured we have first-hand information about this upcoming exploit and we will set the record straight and keep you flowing with the facts as they become available. bguerville has provided us with some details about this release and also tells us about what they plan to release first and that is coming in the next 24 hours in the form of a IDPS Dumper for 4.81 (All PS3 Models). (UPDATE >> Released)

    Additional details via @bguerville
    (NOTICE - Please Read ALL TABS contains IMPORTANT Details about the project !!! )

    • I started investigating the ps3 webkit about 6/7 months, but at the time, it was only to gather information, I had no idea I would eventually be the one working on it!

      End of August, I gave the information I had to esc0rtd3w & expected he would work on it alone. However, he knew nothing about webkit exploitation & he started to collaborate with W. By hijacking webkit, we inherit its privileges which means we are root & we get access to lv2 syscalls. However the ps3 OS is protected by NX (No eXecute is the bsd/linux equivalent of DEP on Windows), no address randomisation though. Executing our own payload is made impossible by NX but we can still execute code despite NX using ROP (Return Oriented Programming).


      The principle is simple, select snippets from the system code (snippets like these are called gadgets) & assemble them so execution jumps from one gadget to the next until the task we planned is done. It requires providing values/parameters & offsetting to each gadget instruction as well...


      First week of September, I joined their effort & 2 weeks later we had ROP execution.
      From that moment, I have been doing all the ROP development work alone while the other 2 helped with testing & researching (and debugging for esc0rtd3w).


      Right now I have 2 ROP chains ready, one for idps dumping & the other for flash memory dumping.

      The next part of the job is to modify the flash dumper into a flash writer.
      When that is done & released, ps3 hardware flashers will have become mostly obsolete.

      FYI, the idps dumper should work on any nor/nand model of ps3. Same goes for the flash memory dumper.

      It was tested ok on superslim.

      Once the ROP work above is finished , there is much more to be done & hopefully more releases to come...

      Stay tuned.....


    • The Current Status

      For now the main project we are working on will not jailbreak all consoles.

      It will enable flash dumps from all consoles but flash write only to all consoles up to 25xx so consoles that are are not cfw compatible will not really benefit just yet, except for dumping flash & idps but not for JB.


      For those with cfw compatible consoles on ofw, once flash is overwritten with a db ofw copy, a user can reboot then install the cfw of their choice. Hardware flashers being then obsolete.. You could also overwrite the flash memory in more recent consoles but that would result in a brick due to metldr2.

      It's only after that flash management project is done, in hopefully March that we will begin working on exploiting lv2. If we get the results we wish, we should be able to make a TaiHEN type of hack for all consoles including superslims.


      Once lv2 is exploited, I am not sure yet how far I will take it, whether I will also try to take on lv1.. Or leave it for someone else to build on by releasing a fully commented & dev friendly version... We will see how things go, ......


      However, even without lv1, direct access to lv2 functions using the right parameters would allow us to run homebrews (except those needing lv1 peek/poke) & backups without problems along with many other things.

    • I figured i would add this (tab) to add some news and thread related to this project, that has arisen after this article.​

    Stay tuned to psx-place.com as this story develops, we have the inside scoop on all the details as they flow. This is a huge breakthrough for the PS3 Community and will only progress from here on out!!!

    UPDATE : IDPS DUMPER HAS BEEN RELEASED> >> NEWS Coverage
    (Please Note - You should not update your PS3 firmware past 4.81 if a Software Update goes Live)
     
    Last edited: Nov 13, 2017

Comments

Discussion in 'PS3 News' started by STLcardsWS, Nov 9, 2017.

    1. esc0rtd3w
      esc0rtd3w
      let it begin! :D

      A HUGE THANK YOU TO ALL INVOLVED!!!
      sanusi, Amaan Khan, MimounEH and 11 others like this.
    2. STLcardsWS
      STLcardsWS
      Lots of good things are coming from this :) Lots of work by these guys as well.
    3. amaandeep.nz
      amaandeep.nz
      Was following this from 2 months excited but I have emmc so nothing for me it was a waste of time for me

      Sent from my SCL-L02 using Tapatalk
      DeViL303 and esc0rtd3w like this.
    4. esc0rtd3w
      esc0rtd3w
      i think if you just install HDD it will work. This is not tested though. We are working on getting support for EMMC soon. Please be patient a little longer :-p
    5. amaandeep.nz
      amaandeep.nz
      I have a hdd running and I don't mind waiting a little longer

      Sent from my SCL-L02 using Tapatalk
      esc0rtd3w likes this.
    6. sandungas
      sandungas
      24 hours for the party !!!
    7. STLcardsWS
      STLcardsWS
      Could be less
      DeViL303, amaandeep.nz and esc0rtd3w like this.
    8. halocraftor
      halocraftor
      The goal is still end of the year? Cause it says 2018 Q?
      DeViL303 likes this.
    9. sandungas
      sandungas
      Some people are not going to be able to sleep today, lol
    10. amaandeep.nz
      amaandeep.nz
      I am one of them [emoji23][emoji23][emoji23][emoji23][emoji23][emoji23]

      Sent from my SCL-L02 using Tapatalk
      sandungas likes this.
    11. STLcardsWS
      STLcardsWS
      1st Quarter of 2018
      esc0rtd3w likes this.
    12. 1986panzi1986
      1986panzi1986
      am not gonna sleep until the end of 2018
      Last edited: Nov 17, 2017 at 2:03 PM
      k9mo and sandungas like this.
    13. halocraftor
      halocraftor
      Thanks it was a ! For some reason

      Sent from my ONEPLUS A3000 using Tapatalk
      k9mo likes this.
    14. k9mo
      k9mo
      @esc0rtd3w and @bguerville congrats for you release soon and you plans for 2018 but my question is concerning the idps dumper will it work on emmc consoles as even you change hdd it stays emmc i know the flash dumper wont work for emmcbut the idps dumper will it work for all consoles including emmc
    15. bguerville
      bguerville
      I believe it will work just fine as soon as I get hold of the emmc lv2 Deviceid required to read it. It must be in lv2kernel.self I guess, need to look... Unless someone knows it & decides to share that info, I would of course welcome it...
      Once I have it, I can make this dumper for emmc in about.... 30s... Then test emmc r/w capabilities. For instance, the NAND seems to read max 2Mb at a time, the NOR only 1Mb max so emmc might also have that kind of max read size, I will need to find out what those are but I don't expect a big challenge...

      For the idps dumper it makes no difference because we only need to extract 512 bytes of flash memory to extract 16 little bytes. The max read would never be reached in any circumstances but for a full flash dumper we require this data.
      Last edited: Nov 11, 2017
    16. aneesh
      aneesh
      Can i exactly know whats gonna be released tonight?
      Just to confirm, if i have a cfw hackable console on 4.81ofw, can i downgrade it to 3.55 without using e3 flasher? Kindly confirm.
      Keep up the good work :)
      thanks in advance
      amaandeep.nz likes this.
    17. amaandeep.nz
      amaandeep.nz
      Will the dumper work on emmc

      Sent from my SCL-L02 using Tapatalk
    18. STLcardsWS
      STLcardsWS
      Right now only the IDPS dumper is set to release within the next 24 hrs , then later on the flash dumper (which will write soon as work is completed.

      from 1st post
    19. bguerville
      bguerville
      Sorry I answered this one question because it was important to clarify. I will do so again if I deem a question really needs to be answered for clarity"s sake.
      Apart from that I will not engage in a Q/A exercise at this stage. You will know more when it's time & not before.

      This release is symbolic, it replaces the stupid leak that does not work with a proper release but I need you to understand, this was not what we had planned. Anyhow now the cat is out of the bag so, come what may, enjoy this release but there will be NO support from me on it.
      Support will come but only at release time like it says in OP, planned for Q1 2018.
      Consider the exploit coming in a few hours a taste of things that may come...

      In the meantime think about it, I can spend time replying & satisfying everyone's curiosity in a marathon of questions OR I can spend time making ROP chains...
      What do you think I should be doing?
      Last edited: Nov 11, 2017
      ed89, DeViL303, STLcardsWS and 6 others like this.

Share This Page